SSH Key Fingerprint
Calculate SHA256 and legacy MD5 fingerprints from an OpenSSH public key
Checks one public-key line and its field structure, not ownership or trust. Private keys are not accepted.
SHA256, MD5, key type, bits/curve, and comment will appear here.
About this tool
SSH Key Fingerprint reads one OpenSSH public-key or authorized_keys line up to 1 MB. It recognizes RSA, DSA, Ed25519, NIST P-256/P-384/P-521 ECDSA and OpenSSH Ed25519/P-256 security-key formats. It checks declared and embedded types, required fields, positive minimal mpints, supported curve names, public-key byte lengths and complete blob consumption. SHA256 and legacy MD5 cover only the binary blob. Quoted authorization options are skipped when selecting the key; the displayed public-key material omits those restrictions and must not replace an existing authorized_keys entry. These are format checks, not proof of key ownership, valid elliptic-curve points, subgroup properties or trust. Private keys, OpenSSH certificates and multiple lines are rejected.
Scenario Recipes
Compare a deployment key without dropping authorization restrictions
Goal: Confirm the key identity while preserving its authorized_keys policy
- Paste one public-key or authorized_keys line.
- Compare its SHA256 fingerprint through a separate trusted channel.
- Keep the original authorization options when approving or editing the entry; use the host-key trust process for server host keys.
Result: A compared public-key identity with its original access restrictions preserved.
Production Snippets
Compare a public fixture with ssh-keygen
text
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICZ91s1xQO72WbF5R/kzTMNLo8c5UJfJDRAMWWHN7bFv round6-public-test
Expected SHA256:svyAwCPWAbBuFzNxMRwUxCAVabdTvyHK5IKI3RkjcWU
Save as fixture.pub, then run: ssh-keygen -lf fixture.pub
Changing the comment does not change the fingerprint. A blob containing only ssh-ed25519 with no 32-byte key must fail.Frequently Asked Questions
Which SSH public-key formats are accepted?
Use one OpenSSH RSA, DSA, Ed25519, NIST ECDSA or supported OpenSSH security-key public line. An authorized_keys option list may precede it, including quoted command values. Multi-line lists and certificates are not supported.
Does the fingerprint include the comment?
No. OpenSSH fingerprints hash the binary key blob; the trailing user@host comment is display metadata.
Why are SHA256 and MD5 both shown?
SHA256 is the modern OpenSSH default, while MD5 helps compare older inventories and console output.
Can it read a private key?
No. Private-key blocks are explicitly rejected and are not needed to calculate a public-key fingerprint.
Are OpenSSH certificates supported?
No. Certificate key types contain additional signed fields and are intentionally rejected by this public-key parser.
Is the key uploaded?
No. Base64 decoding, blob validation, bit inspection, SHA256, and MD5 calculation all run locally.
Can I replace authorized_keys with the displayed public-key line?
No. The displayed material omits from, command, restrict and other authorization options. Keep the original restricted entry and compare the fingerprint separately. Host keys belong to the host-trust workflow, not a user authorized_keys file.
Does a fingerprint prove the key is trusted or mathematically valid?
No. The tool checks field structure and fingerprints bytes. It does not prove private-key possession, evaluate curve points or DSA groups, or establish a trusted identity. Compare SHA256 through a separate trusted channel.
Keep browsing